CVE-2024-43532
Last Modified: 9 Jun 2026Remote Registry Service Elevation of Privilege Vulnerability
CVE-2024-43529
Last Modified: 9 Jun 2026Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2024-43527
Last Modified: 9 Jun 2026Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-43526
Last Modified: 9 Jun 2026Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2024-43525
Last Modified: 9 Jun 2026Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2024-43519
Last Modified: 9 Jun 2026Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2024-43518
Last Modified: 9 Jun 2026Windows Telephony Server Remote Code Execution Vulnerability
CVE-2024-43515
Last Modified: 9 Jun 2026Internet Small Computer Systems Interface (iSCSI) Denial of Service Vulnerability
CVE-2024-43513
Last Modified: 9 Jun 2026BitLocker Security Feature Bypass Vulnerability
CVE-2024-43508
Last Modified: 9 Jun 2026Windows Graphics Component Information Disclosure Vulnerability
CVE-2024-43506
Last Modified: 9 Jun 2026BranchCache Denial of Service Vulnerability
CVE-2024-43505
Last Modified: 9 Jun 2026Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2024-43504
Last Modified: 9 Jun 2026Microsoft Excel Remote Code Execution Vulnerability
CVE-2024-43503
Last Modified: 9 Jun 2026Microsoft SharePoint Elevation of Privilege Vulnerability
CVE-2024-43502
Last Modified: 9 Jun 2026Windows Kernel Elevation of Privilege Vulnerability
CVE-2024-43481
Last Modified: 8 Jul 2025Power BI Report Server Spoofing Vulnerability
CVE-2024-43480
Last Modified: 9 Jun 2026Azure Service Fabric for Linux Remote Code Execution Vulnerability
CVE-2024-38261
Last Modified: 9 Jun 2026Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-38179
Last Modified: 9 Jun 2026Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
CVE-2024-43516
Last Modified: 9 Jun 2026Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2024-38097
Last Modified: 8 Jul 2025Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2024-3057
Last Modified: 15 Apr 2026A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.
CVE-2024-8626
Last Modified: 10 Oct 2024Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.
CVE-2024-47011
Last Modified: 16 Oct 2024Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
CVE-2024-47010
Last Modified: 16 Oct 2024Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
CVE-2024-47009
Last Modified: 16 Oct 2024Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
CVE-2024-47008
Last Modified: 16 Oct 2024Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-47007
Last Modified: 16 Oct 2024A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-9167
Last Modified: 13 Aug 2025Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
CVE-2024-9381
Last Modified: 16 Oct 2024Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
CVE-2024-9380
Last Modified: 24 Oct 2025An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
CVE-2024-9379
Last Modified: 24 Oct 2025SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
CVE-2024-9124
Last Modified: 22 Sept 2025A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavailable. The device may require a power cycle to recover it if it does not re-establish a connection after it stops receiving requests.
CVE-2024-7612
Last Modified: 18 Dec 2024Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
CVE-2024-47951
Last Modified: 11 Oct 2024In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
CVE-2024-47950
Last Modified: 11 Oct 2024In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
CVE-2024-47949
Last Modified: 11 Oct 2024In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
CVE-2024-47948
Last Modified: 11 Oct 2024In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
CVE-2024-47161
Last Modified: 11 Oct 2024In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
CVE-2024-8215
Last Modified: 16 Oct 2024Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51.
CVE-2024-45330
Last Modified: 19 Oct 2024A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests.
CVE-2024-33506
Last Modified: 21 Jan 2025An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
CVE-2024-9625
Last Modified: 11 Feb 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-8431
Last Modified: 15 Apr 2026The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve private post titles.
CVE-2024-8482
Last Modified: 8 Apr 2026The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-9207
Last Modified: 15 Apr 2026The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2024-8488
Last Modified: 8 Apr 2026The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVE-2024-8884
Last Modified: 15 Apr 2026CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network over http
CVE-2024-9005
Last Modified: 15 Apr 2026CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server.
CVE-2024-8518
Last Modified: 15 Apr 2026CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded by an application user.
